2022-04-20 | CBE13.2

Added · Updated

CBE Regulation Book 13.2 - The Rules Regulating The Provision Of Internet Banking Services

The Central Bank of Egypt establishes rules for internet banking services, requiring banks to implement risk management frameworks, secure authentication methods, and anti-money laundering protocols. The regulation mandates strict identity verification, password security standards, and specific controls for fund transfers and third-party outsourcing. It also outlines board responsibilities and introduces temporary measures to facilitate electronic payments during the coronavirus pandemic.

Central Bank of Egypt logo

Egypt

Central Bank of Egypt

Click to view thumbnail

Chapter Two: Rules Regulating the Provision of Internet Banking Services

1. Introduction

1-1 Purpose

Electronic banking services have become one of the fundamental elements of many banking services, as customer expectations create pressure on banks to adopt new banking strategies. The term "electronic banking" refers to the automated and computerized delivery of traditional banking products and services to achieve direct benefit for customers through interactive electronic communication channels. Electronic banking includes the necessary systems that enable bank customers, whether individuals or legal entities, to access their accounts, conduct their transactions, or obtain information about financial products and services through electronic communication channels.

Although a malfunction or disruption in electronic banking services may not affect the stability of the financial system, it negatively affects customer confidence in the services provided through communication channels and threatens the bank's reputation. The rules governing banks help provide these services in a manner that maintains the confidentiality and security of information and allows customers to rely on them by appropriately controlling and securing the infrastructure.

To increase the tendency of banking services in Egypt towards relying on technology, more regulatory reforms are required in this field.

2-1 Scope of the Rules

  • Although the risks and controls are similar across different communication channels for banking services, these rules specifically apply to Internet Banking Services (also known as Internet Banking) used by customers, whether individuals or legal entities.

  • The scope of the rules does not cover other execution channels (e.g., Automated Teller Machines (ATMs), landline banking services, and mobile banking services), and detailed rules governing these services will be issued separately later.

  • These rules and controls represent the minimum required to provide Internet banking services securely. All banks must not rely solely on this and must ensure that all necessary measures are taken regarding the management of risks associated with providing this type of banking service.

  • These rules include some general controls or supervisory objectives related to business continuity, outsourcing of work, and information system risk management. However, detailed rules governing these areas will be issued separately later.

  • These rules do not cover debit card transactions conducted through the four-party system (Four-Party Model) and payment transactions from closed systems conducted via the Internet.

  • These rules apply to the provision of Internet banking services without prejudice to the supervisory controls for electronic banking operations previously issued by the Central Bank, as well as the instructions and rules for executing banking operations.

  • These rules apply to all banks registered with the Central Bank of Egypt, including branches of foreign banks.

3-1 Appendices

  • Appendix (A): Best Practices for Internet Banking Infrastructure Setup
  • Appendix (B): Examples of the Most Common Electronic Attacks
  • Appendix (C): Definitions

2. Internet Banking Services Risk Management

1-2 Risks Associated with Internet Banking Services

The provision of Internet banking services is accompanied by many risks and advantages simultaneously. While these risks are not new to banks, the characteristics of Internet banking services may increase risk levels and create new challenges for managing these risks. These risks include, but are not limited to:

Strategic Risks

These involve the decision to provide Internet banking services, the type of services provided, and the appropriate timing for their provision. This specifically refers to the economic feasibility of providing or continuing these services and whether the return on investment will exceed initial investments and the costs of continuing to provide these services. Poor planning for Internet banking services and unwise investment decisions can increase the strategic risks banks face.

Operational Risks / Transaction Risks

These arise from fraud or errors in transaction execution, system failures, or other unexpected events that may prevent the bank from providing services or expose the bank or its customers to financial losses. While risks exist in all products and services provided, the level of transaction risk is affected by the structure of banking procedures and transactions, including the types of services provided, the degree of operational complexity, and the technological aids used.

Compliance Risks / Legal Risks

These risks arise from the rapid increase in the use of Internet banking services and the difference between electronic and manual operations. Regulatory/legal challenges may include:

  • Entering into a legal agreement electronically with customers to use the Internet banking service.

  • The methods banks use to verify customer identity, considered a source of legal risk that requires adequate controls to mitigate.

  • In light of banks' commitment to the Central Bank Law, banks must establish procedures and controls to maintain data privacy and account confidentiality to manage the increasing risks associated with providing Internet banking services. This also includes the legal liability of banks towards customers due to the possibility of data privacy breaches or other problems caused by hacking, fraud, or other technological failures, and to protect that data from theft.

  • Banks providing Internet banking services bear a higher degree of compliance risk due to the changing nature of technology and regulatory amendments aimed at addressing issues specific to providing this type of service.

  • Retaining required compliance documents related to records, applications, account statements, disclosures, and notifications.

  • Identifying and assessing money laundering and terrorist financing risks that may arise from banking services provided via the Internet. This assessment must be completed before launching Internet banking services.

Reputational Risks

The level of reputational risk increases significantly as a result of the bank's decision to provide Internet banking services, especially for more complex transactions. Some risks that may affect the bank's reputation through the provision of Internet banking services include:

  • Lack of trust due to unauthorized transactions on the customer's account.

  • Disclosure of confidential customer information to unauthorized parties or its theft.

  • Failure to provide reliable services due to repeated service disruptions or long downtime.

  • Customer complaints regarding the difficulty of using Internet banking services or the inability of bank support staff to resolve these issues.

Information Security Risks

This type of risk arises from the possibility of unauthorized parties exploiting weaknesses in the electronic system to cause harm, resulting in effects related to the integrity, availability, and confidentiality of data.

2-2 Responsibilities and Obligations of the Board of Directors and Senior Management

1-2-2

The Board of Directors and Senior Management are responsible for overseeing the preparation of the bank's business strategy and making a clear strategic decision regarding the bank's desire to provide Internet banking services. Specifically, the Board of Directors must ensure the following:

  • Internet banking plans align with the bank's strategic objectives.

  • Risk analysis of the proposed Internet banking services.

  • Preparation of appropriate procedures to monitor and mitigate risks related to identified risks.

2-2-2

The Board of Directors and Senior Management must ensure that risks associated with Internet banking services mentioned in Item 1-2 are analyzed and mitigated appropriately, as follows:

1-2-2-2

Establish effective controls over risks associated with providing Internet banking services, including defining responsibilities, policies, and supervisory controls to manage these risks:

  • The Board of Directors and Senior Management must be aware of Internet banking operations, which may present challenges different from traditional risk management as described in Item 1-2.

  • The Board of Directors and Senior Management must ensure that the bank does not provide new Internet banking services or adopt new technological means unless the bank has the necessary expertise to manage risks efficiently. Employee and management expertise should match the technical nature and degree of complexity of applications and technologies specific to Internet banking services.

  • The Board of Directors and Senior Management must determine the bank's risk appetite regarding Internet banking services and ensure that risk management processes related to these services are included in the bank's general risk management methodology. Existing policies and processes related to risk management must be reviewed to ensure they are sufficient to cover new risks that may arise from Internet banking services.

  • Internal Audit Management must provide the Board of Directors, the Audit Committee, and Senior Management with an independent and objective assessment of the effectiveness of supervisory controls applied to mitigate risks resulting from providing Internet banking services, including technology risks.

2-2-2-2

Review and approve the main aspects of the bank's security control process:

  • The Board of Directors and Senior Management must oversee the continuous development and maintenance of the security control infrastructure that provides appropriate protection for Internet banking services' systems and data from any internal or external threats. To ensure the effectiveness of securing Internet banking services, the Board of Directors and Senior Management must ensure the following actions are taken:

  • Define clear responsibilities regarding the supervision of the establishment and management of the bank's security policies.

  • Provide necessary protection to prevent unauthorized persons from entering the computing environment, which includes all vital systems, network servers, databases, applications, communications, and security systems for Internet banking services.

  • Provide necessary electronic controls to prevent any unauthorized internal or external parties from accessing applications and databases for Internet banking services.

  • Periodically review security procedures and system testing operations (e.g., conducting periodic penetration testing as mentioned in Item 8-3), including continuous monitoring of developments in security systems in this field, and downloading and preparing appropriate software updates and service packs and necessary measures after conducting required tests.

3-2-2-2

Establish a comprehensive and continuous mechanism for conducting Due Diligence research and supervising outsourcing operations and the bank's relationships with other external parties relied upon to provide Internet banking services. The Board of Directors and Senior Management should focus on the following points, including but not limited to:

  • Full awareness of the risks resulting from entering into any arrangements regarding outsourcing or partnership concerning Internet banking services' systems or applications, in addition to providing necessary resources to supervise these arrangements.

  • Conducting necessary due diligence research regarding the competence, system infrastructure, and financial capacity of the partner or external service provider before entering into any outsourcing or partnership agreements.

  • Clearly defining contractual responsibilities for all parties to outsourcing or partnership agreements. For example, responsibilities for providing information to the service provider and receiving information from it are clearly defined.

  • Outsourcing service contracts include a non-disclosure agreement for confidential information to external parties and a service level agreement, which includes, but is not limited to, defining roles and responsibilities, the time required to execute the service, escalation procedures and data, and penalties for non-compliance. This is in addition to clauses preserving the bank's right to audit service providers or rely on audits issued by approved auditing bodies.

  • All systems and processes for Internet banking services conducted through outsourcing are subject to the bank's risk management system and privacy and information security policies that align with the bank's standards.

  • Internal and/or external audits are conducted periodically on operations conducted through outsourcing. The scope of audit work should not be less than that applied at the internal level within the bank.

  • All audit and evaluation reports are provided to the inspectors of the Supervision and Oversight Sector of the Central Bank of Egypt.

  • Appropriate contingency plans are established for Internet banking services conducted through outsourcing.

  • Termination/cancellation procedures are effective and must ensure the preservation of business continuity, data integrity, as well as its transfer and disposal.

  • If Internet banking services are outsourced to entities outside the Arab Republic of Egypt, banks must take necessary measures to comply with Egyptian laws, legislation, and the jurisdiction of Egyptian courts regarding any disputes that may arise.

According to Item 2-1, detailed rules governing outsourcing activities will be issued separately, including detailed supervisory controls, supervisory objectives, and a list of systems and services allowed to be outsourced. Until these rules are issued, banks must not enter into any agreements related to outsourcing Internet banking services or their applications without obtaining prior approval from the Central Bank of Egypt.

3-2 Establishing an Information Security Policy

1-3-2

Senior Management must ensure that the information security policy applied at the bank is approved by the Board of Directors and is updated periodically to cover Internet banking services. This contributes to identifying the policies, procedures, and supervisory controls necessary to protect banking operations from breaches and security violations. It also defines individual responsibilities and clarifies implementation mechanisms and procedures to be taken in case of violation of these policies and procedures.

2-3-2

Senior Management is responsible for enhancing and spreading security culture at all levels of the bank by emphasizing their commitment to high information security standards and spreading this culture among all bank employees.

4-2 Classification of Internet Banking Service Risks

Banks provide a variety of Internet banking services to diverse customer categories, and therefore they usually do not involve the same level of inherent risk. For example, customers allowed only to inquire about their account balances via the Internet are not exposed to the same level of risk as other customers who transfer funds to external accounts.

This diversity in service provision requires banks to adopt comprehensive security methods that are also flexible. The security methodology must be based on analyzing the risks and threats specific to Internet banking services, taking into account inherent risks and compensating controls to reach a residual risk level that falls within the bank's acceptable risk levels.

5-2 Anti-Money Laundering and Counter-Terrorist Financing Rules

Banks providing Internet banking services must implement the following:

  • Compliance with the Anti-Money Laundering Law issued by Law No. 80 of 2002, its executive regulations, and the supervisory controls for banks regarding anti-money laundering and counter-terrorist financing issued by the Central Bank of Egypt in 2008, and the Customer Identification Rules for Banks issued by the Anti-Money Laundering and Counter-Terrorist Financing Unit in 2011.

  • Applying enhanced due diligence procedures for high-risk customers and transactions as stated in Item Eight (Enhanced Due Diligence Procedures for Customer Categories or High-Risk Financial Services and Transactions) of the Customer Identification Rules for Banks issued by the Anti-Money Laundering and Counter-Terrorist Financing Unit in 2011.

  • Giving sufficient attention to the guiding indicators in Item Seven (Guiding Indicators for Identifying Transactions Suspected of Involving Money Laundering or Terrorist Financing) of the supervisory controls for banks regarding anti-money laundering and counter-terrorist financing issued by the Central Bank of Egypt in 2008.

  • In case of suspicion of any transactions conducted via the Internet, notifying the Anti-Money Laundering and Counter-Terrorist Financing Unit thereof, in accordance with the provisions of the Anti-Money Laundering Law issued by Law No. 80 of 2002.

3. Supervisory Controls on Internet Banking Services

1-3 Management of Internet Banking Service Accounts

1-1-3

Banks are committed to not allowing new customers (those who do not have a bank account or an Internet banking service account) to open a bank account using any of the electronic service delivery channels (e.g., the bank's website, etc.). Banks must apply the Customer Identification Rules for Banks issued by the Anti-Money Laundering and Counter-Terrorist Financing Unit in 2011 to these new customers.

2-1-3

Banks obtain a handwritten signature from the customer wishing to subscribe to Internet banking services on the service request form(s) or contract(s) containing the customer's basic data as a minimum (e.g., email address, mobile and landline phone numbers, mailing address, etc.), in addition to the terms and conditions that clearly define the rights and obligations between the bank and customers (please refer to Item 1-4).

3-1-3

Banks are committed to using reliable methods to verify the identity and authority of customers wishing to subscribe to Internet banking services, as well as verifying the identity and authority of subscribed customers wishing to conduct banking activities via Internet banking services.

4-1-3

Banks are committed to applying all procedures and supervisory controls that enable them to identify the identity of anyone conducting any electronic transactions related to bank accounts, in cases where more than one user is authorized to transact on this account.

5-1-3

Banks are committed to obtaining all necessary legal documents to prove the authorization of authority for users to conduct transactions on legal entity accounts.

6-1-3

Banks are committed to conducting necessary audits to verify the customer's identity when they request a modification to their Internet banking service account data or modify any data they use to monitor their banking account activities.

This applies to account reactivation, re-issuing a new password for an Internet banking customer, and changing the customer's contact information such as email address, mobile and landline phone numbers, and mailing address. Banks must also consider applying the following standards when dealing with these requests:

1-6-1-3

If the customer submits a request to modify their data at a branch, the necessary procedures must be applied to verify their identity.

2-6-1-3

For modification requests submitted via Internet banking services, the authentication method mentioned in Item 2-3 must be used, ensuring the existence of effective monitoring mechanisms.

3-6-1-3

Banks must apply necessary procedures to verify the customer's identity when they receive information, tools, or devices that allow them to access their Internet banking account (e.g., PIN, security token devices, etc.).

4-6-1-3

In the absence of similar standards to those mentioned above, banks must avoid sending important documents (e.g., checkbooks, alternative security token devices, etc.) to customers who have recently changed their mailing addresses. The customer is obligated to collect these documents themselves from a bank branch after verifying their identity according to applicable rules.

5-6-1-3

Conduct additional verification and inspection to verify the customer's identity, particularly for requests conducted via telephone (calls received from customers only) to send new security token devices or any other important documents. An example of additional verification includes asking the customer for information that changes from time to time, in addition to questions related to personal details in general (e.g., approximate account balances and the last transactions executed on the account).

In order for the Central Bank of Egypt to maximize the effective contribution of the banking sector in implementing the state's plan to deal with the repercussions of the coronavirus, and starting from the role of the banking sector in encouraging the use of electronic means and channels for payment, which would facilitate financial transactions for citizens and contribute to limiting the spread of the virus, banks have been directed to take necessary measures to implement the following:

A. The bank may register its current customers in this service after verifying their identity according to the usual electronic verification methods used for any of its products, including but not limited to (authentication using the secure code for payment cards or authentication data for the Internet banking service, etc.).

B. The customer is obligated to complete what is necessary to comply with the bank's procedures for subscribing to this service within the period deemed appropriate by the bank, based on their assessment of the risks associated with these services.

C. The bank must determine the banking services made available to customers enrolled in the service according to Item (A) mentioned above, based on their assessment of the risks associated with these services, while following the other specific controls in these rules.

2-3 Identity Verification Means (Authentication)

1-2-3

Banks are committed to using effective and reliable means to verify the identity of customers using Internet banking services. Authentication is usually more effective when combining two of the following elements:

  • Something known to the customer (e.g., username and password).

  • Something possessed by the customer (e.g., digital signature or one-time passwords issued using security token devices).

  • A distinctive characteristic specific to the customer (e.g., biometric traits, such as fingerprints).

2-2-3

Banks must re-authenticate using two means together (e.g., digital signature or one-time passwords issued using security token devices) when executing high-risk activities (such as transferring funds to external parties, registering new beneficiaries, changing customer contact data, etc.). The authentication means used must work in conjunction with other applied controls to enhance the following dimensions:

  • Non-repudiation
  • Data integrity
  • Data confidentiality
  • Identity validity

3-2-3

Banks must determine the authentication means they will use for Internet banking services based on an analysis of risks associated with the system, taking into account the assessment of the type of banking transactions provided via Internet banking.

4-2-3

Banks need to conduct a precise assessment to determine if the authentication means used is secure enough, even if the customer's personal computer is exposed to threats, such as malicious software like Trojans and spyware via keystroke logging.

5-2-3

Banks must use appropriate technology to create passwords, in addition to applying necessary means to maintain password confidentiality when delivered to the customer, as mentioned in Item 3-3.

6-2-3

Banks must also apply appropriate means that enable customers to verify the identity and credibility of the bank's electronic websites, in addition to customer identity authentication standards. This is done by installing digital certificates and their associated keys from known and trusted authorities on the Internet banking system servers. The use of certificates that include additional validation/confirmation is recommended.

7-2-3

Banks must create a mechanism for verifying authentication as follows:

1-7-2-3

Notify the customer immediately upon entering the system of previous successful and/or failed attempts for the customer's username, immediately upon the customer entering the system.

2-7-2-3

Prevent user access to Internet banking services after a specified number of failed attempts - not exceeding five attempts. The bank must prepare clear procedures for reactivating the suspended user account.

3-7-2-3

Prevent the user from using more than one usage window simultaneously.

4-7-2-3

Do not provide any information after failed attempts to access the system to the person who made those attempts, such as disclosing the non-existence of this username or that the password is incorrect.

5-7-2-3

Regularly monitor successful and/or failed login attempts for Internet banking services. Upon discovering any serious violation, an investigation must be conducted, potential threats identified, and necessary measures taken.

3-3 Password Management

1-3-3 Password Specifications:

Banks must observe the following supervisory measures when dealing with customer passwords:

  • Apply dual control and/or segregation of duties for the process of creating passwords and delivering them to customers, and the process of activating Internet banking service accounts.

  • Enhance the security of the password creation process to ensure it is not exposed.

  • Ensure that passwords are not processed, sent, or stored in clear text.

  • Internet banking system users and managers must be directed to change the issued password immediately upon first login to the system.

  • Apply password expiration rules based on a validity period predetermined by the bank.

  • Maintain a history of used passwords and ensure they are not reused again within a number of times or duration specified by the bank.

  • Enforce the use of complex passwords (e.g., consisting of eight characters including letters, numbers, and special symbols, etc.).

  • The password must be encrypted using a strong encryption mechanism or the encryption key length must be appropriate (not less than 1024 bits).

  • Use appropriate technology to create passwords and adopt appropriate technologies to maintain their security during electronic delivery to the customer, either manually or electronically.

  • Ensure that the "remember password" mechanism cannot be used (i.e., do not allow storing the password as a site-specific application code or in password cookie files).

2-3-3 One-Time Passwords Issued Using Security Token Devices

  • Minimum password specifications for one-time passwords:

    • The password must not be less than 6 characters.
    • The time limit for using the password must not exceed 90 seconds.
    • Ensure that the algorithm solution system for creating passwords provides sufficient randomness of symbolic values.
  • The security token device must be protected by a PIN according to the following:

    • The PIN for the security token device must not be less than 4 digits.
    • Easy numbers should not be allowed as a PIN (e.g., 1111 or 1234).
    • There must be a maximum limit for unsuccessful PIN entry attempts - not exceeding five attempts - before the security token device is suspended.
    • Banks must prepare clear procedures for issuing initial PINs and reactivating suspended security token devices.
    • The customer must be directed to change the PIN upon first use if it is issued by the bank.

4-3 Controls for Fund Transfer Operations

1-4-3

Must


[RegAlert note: the English text above is a translation of the first 24,000 characters of a 92,595-character original (26% of the document). The remainder was not translated. The complete original-language text is stored with this document.]

More like this from CBE

CBE published 2 documents in the last 30 days. We email you each new one the day it's published.

Share